ESET researchers have identified a new variant of NGate malware that exploits the legitimate HandyPay app on Android. Spread since November 2025, it affects users in Brazil via fake sites (lotteries and Google Play). Probable use of GenAI to infect the app and spread the trojan
ESET Research has discovered a new variant of the NGate malware family that exploits a legitimate Android application called HandyPay, rather than the previously used NFCGate tool. The attackers took the app, used to transmit NFC (Near Field Communication) data, and modified it by inserting malicious code that appears to have been generated by AI. As in previous NGate variants, the malicious code allows attackers to transfer NFC data from the victim's payment card to their device and use it for contactless withdrawals from ATMs and unauthorized payments. Furthermore, the code is capable of capturing victims' payment card PINs and sending them to the operators' command and control server. The threat targets users in Brazil but NFC-based attacks are expanding to new regions.
The malicious code used to infect HandyPay with a Trojan appears to have been created with the help of generative AI (GenAI) tools. Specifically, the malware logs contain an emoji typical of AI-generated texts, suggesting that built-in Large Language Models (LLMs) were involved in generating or modifying the code, although there is no definitive evidence yet. This is part of a broader trend in which GenAI would reduce barriers to entry for cybercriminals, allowing hackers with limited technical expertise to produce working malware.
ESET Research believes that the distribution campaign of the Trojan-infected HandyPay began around November 2025 and is still active. It should also be noted that the maliciously modified version of HandyPay was never available on the official Google Play Store. As a partner of the App Defense Alliance, ESET shared its findings with Google. ESET has also contacted the developers of HandyPay to warn them about malicious use of their application.
The increase in NFC threats has led to a consolidation of the ecosystem that supports them. Early NGate attacks used the open source NFCGate utility to facilitate NFC data transfer. Since then, several versions of malware-as-a-service (MaaS) with similar functionality have been made available to the public. However, in this campaign the attackers decided to opt for their own solution, applying a malicious patch to an existing app, the HandyPay one.
«Why did the authors of this campaign decide to infect the HandyPay app with a Trojan instead of using an established solution for NFC data transfer? The answer is simple: money. Subscription costs for existing MaaS kits run into the hundreds of dollars: NFU Pay advertises its product at nearly $400 per month, while TX-NFC offers it for around $500 per month. On the other hand, the legitimate HandyPay app is significantly cheaper, requiring a donation of just €9.99 per month, if not even less. Besides the price, HandyPay “does not ask for any permission other than to be set as the default payment app, thus helping the threat actors not to arouse suspicion,” says ESET researcher Lukáš Štefanko, who spotted the new NGate variant in the infected NFC payment app.
The first new NGate champion is released via a website that presents itself as Rio de Prêmios, a lottery operated by the Rio de Janeiro state lottery (Loterj). The second NGate sample is distributed via a fake Google Play webpage in the form of an app called Proteção Cartão (Card Protection). Both websites resided on the same domain, which strongly suggests the existence of a single threat actor. The malware uses the HandyPay service to forward NFC card data to a device controlled by the attacker. In addition to transmitting NFC data, the malicious code also steals payment card PINs, allowing the attacker to use the victim's payment card data to withdraw cash from ATMs.






